What is Strategic Risk?
Strategic risk is the risk that an organization’s long-term objectives, business model, or strategic decisions will fail to deliver expected outcomes due to internal weaknesses, flawed assumptions, or external changes in the political, economic, technological, legal, or competitive environment. It includes areas where management’s vision meets uncertainty, and where errors in judgment, alignment, or adaptation can have existential consequences.
Internal strategic risk arises from decisions made within the organization, like flawed business models, overexpansion, neglect of compliance, poor culture, or weak governance. It reflects the organization’s own capacity to plan and execute effectively.
External strategic risk arises from forces outside the organization’s control that alter the environment in which strategic decisions are made. This includes geopolitical realignment, political instability, regulatory transformation, technological disruption, or societal shifts in expectations and values.
Strategic risk involves decisions deliberately taken at the highest level. It is not an operational or compliance risk, which describe failure to execute processes. Strategic risk describes what the organization chooses to do (and what it chooses not to do). It reflects the organization’s exposure to long-term uncertainty that cannot be mitigated through procedural controls.
The duty of care and the duty of loyalty
The duty of care and the duty of loyalty are critical in strategic risk management. These two fiduciary duties define how boards and executives must identify, evaluate, and act, in order to preserve the organization’s legitimacy, resilience, and long-term value.
The duty of care requires directors and senior executives to act with diligence and prudent judgment when setting, approving, or revising the organization’s strategy. It obliges them to ensure that strategic decisions are based on a robust understanding of risks, opportunities, and external dependencies.
In the context of strategic risk, the duty of care demands that boards do more than simply endorse management’s proposals. They must critically evaluate the underlying assumptions, examine sensitivity analyses, and stress test the resilience of strategic plans under alternative scenarios, including geopolitical shifts, regulatory change, technological disruption, reputational crises, and hybrid risks.
When a board fails to exercise this level of scrutiny, it risks a breach of its duty of care. A decision that is uninformed, rushed, or made without appropriate expert advice may later be deemed negligent, even if it was taken in good faith. The law does not expect directors to predict the future, but it does expect them to demonstrate a disciplined process of foresight and oversight.
Directors must understand strategic exposures arising from cyber and hybrid threats, regulatory evolution, sustainability transitions, and technological dependence. A board that lacks the expertise to oversee these dimensions of risk has a duty to seek education, external advice, or board renewal to close the knowledge gap. Ignorance of material risks is no longer a defensible position under contemporary governance expectations.
The duty of loyalty complements the duty of care by addressing motive and alignment. It requires directors to act honestly, in good faith, and in the best interests of the company, placing organizational welfare above personal, political, or short-term interests.
In strategic risk management, the duty of loyalty is expressed through integrity of purpose. Strategic decisions must be guided by the corporation’s long term sustainability, compliance obligations, and legitimate stakeholder interests, not by executive ambition, shareholder pressure, or political convenience.
Breaches of loyalty arise when strategic actions are taken under conflicts of interest. Examples include pursuing acquisitions that benefit insiders, ignoring compliance risks for short-term financial gain, but also concealing information from regulators or investors. Such behavior exposes the organization to strategic risk, undermines trust, erodes legitimacy, and invites regulatory or legal action.
Modern governance frameworks recognize that the best interests of the organization cannot be interpreted narrowly as immediate shareholder value. Under evolving standards and international corporate governance principles, the duty of loyalty requires boards to consider the broader stakeholder ecosystem, including employees, customers, creditors, communities, and the environment. Strategic decisions that neglect these dimensions may jeopardize the company’s long-term viability and reputation.
Strategic risk links the quality of governance processes with strategic judgment. Regulators, courts, and investors increasingly evaluate corporate failures through this fiduciary lens. Was the board informed? Did it act in good faith? Did it exercise independent judgment?
Drivers of strategic risk.
1. Governance and leadership factors include:
- Inadequate board oversight or failure to challenge management assumptions.
- Weak corporate governance or poor alignment between board and executive objectives.
- Deficient risk culture or lack of accountability across leadership levels.
- Poorly defined risk appetite or tolerance for strategic exposure.
- Ineffective succession planning and leadership transition risk.
- Groupthink, overconfidence, or cognitive bias in decision-making.
- Conflicts of interest undermining independent judgment.
- Failure to integrate legal, risk, and compliance functions into strategy formulation.
2. Strategic planning and execution factors include:
- Inaccurate or outdated strategic assumptions.
- Misjudgment of market trends, consumer behavior, or technological disruption.
- Overambitious or unrealistic growth objectives.
- Poor execution of mergers, acquisitions, or integrations.
- Misallocation of capital and resources.
- Failure to adapt the business model to new competitive realities
- Absence of scenario planning or strategic resilience testing.
- Insufficient monitoring of key performance and risk indicators.
3. Regulatory and legal factors include:
- Rapid regulatory change altering the cost structure or business model.
- Non-compliance with new or extraterritorial legal obligations.
- Inadequate anticipation of emerging laws (like data protection, ESG, AI governance).
- Enforcement actions, penalties, or litigation affecting strategic direction.
- Failure to engage in regulatory dialogue or policy intelligence.
- Shifts in legal interpretation or judicial precedent impacting operations.
4. Geopolitical and macroeconomic factors include:
- Political instability, regime change, or conflict in key markets.
- Trade barriers, sanctions, or export control measures.
- Supply chain fragility due to geopolitical fragmentation.
- Inflation, currency volatility, or financial market shocks.
- Sovereign risk, including expropriation or nationalization.
- Changes in tax regimes or international fiscal coordination.
- Disruption from regional integration or disintegration (e.g., Brexit-type events).
5. Technological and digital transformation factors include:
- Disruptive innovation eroding established business models.
- Hybrid and cyber attacks.
- Overreliance on untested or opaque AI systems.
- Insufficient governance of digital ethics and algorithmic accountability.
- Inability to attract or retain digital talent.
- Failure of digital transformation initiatives due to weak change management.
- Technological obsolescence or dependence on single vendors.
6. Environmental, social, and sustainability factors include:
- Failure to adapt to climate transition policies and carbon regulation.
- Reputational backlash from inadequate ESG performance.
- Environmental incidents triggering legal or political intervention.
- Social activism, consumer boycotts, or stakeholder pressure.
- Human rights and supply chain due diligence failures.
- Misalignment between sustainability commitments and operational practice.
- Loss of investor confidence due to greenwashing or non-transparency.
7. Reputational and ethical factors include:
- Ethical misconduct or governance scandals at senior levels.
- Poor crisis communication and stakeholder engagement.
- Mismanagement of public trust during controversy or litigation.
- Perception gaps between corporate behavior and societal expectations.
- Media amplification of operational incidents or compliance failures.
- Disinformation or targeted reputational attacks undermining legitimacy.
8. Financial and structural factors include:
- Excessive leverage or weak liquidity position limiting strategic flexibility.
- Inadequate hedging against interest rate or currency fluctuations.
- Dependence on a narrow revenue base or single market segment.
- Asset impairments or balance sheet vulnerabilities.
- Ineffective capital allocation and risk-adjusted return analysis.
9. Human capital factors include:
- Talent shortages in key strategic or technical areas.
- Cultural misalignment following mergers or restructuring.
- Inadequate diversity, equity, and inclusion at leadership levels.
- Resistance to organizational change or innovation fatigue.
- Erosion of institutional knowledge and succession risk.
10. Emerging and frontier risks factors include:
- Unanticipated systemic shifts such as pandemics or biosecurity crises.
- Frontier technologies (quantum computing, human–AI integration, biotechnology).
- Hybrid or asymmetric threats combining cyber, legal, and informational dimensions.
- Legal uncertainty in areas where regulation has not yet matured.
- Societal transformations altering norms of privacy, autonomy, or liability.
Technological acceleration is a prime driver of systemic risk. Artificial intelligence, automation, quantum computing, and digital ecosystems continuously redefine the boundary between human and machine capabilities. Organizations often fail to anticipate these changes. Those that adopt these technologies without adequate governance face regulatory, ethical, and reputational backlash.
Regulatory transformation is another major source of systemic risk. The tightening of cybersecurity, data protection, ESG, and competition frameworks globally means that regulatory risk has become a structural input into strategy formulation. Firms that treat compliance as an operational afterthought rather than a strategic variable find themselves locked into unsustainable cost structures or facing exclusion from critical markets.
Geopolitical risk and fragmentation of the global order add a further layer of uncertainty. The weaponization of trade, technology, and financial systems transforms what were once neutral commercial decisions into politically charged acts. For multinational corporations, sanctions, export controls, and localization requirements can suddenly render entire business lines illegal or economically unviable.
Reputational and social legitimacy also fall within the domain of strategic risk. The erosion of public trust and stakeholder demands for transparency can compel radical strategic reorientation. The failure of environmental or human rights due diligence, the mishandling of whistleblower claims, or the perception of unethical conduct can escalate from isolated events into full-blown strategic crises.
In simple words, strategic risk is the risk of getting the future wrong. It is the most complex and the most consequential form of risk, because it often originates in the choices of leadership and shapes the destiny of the organization.
Learning from the Annual Reports
Strategic Risk, from the Annual Report, Lloyds Banking Group plc
DEFINITION
Strategic risk is defined as the risk which results from:
• Incorrect assumptions about internal or external operating environments
• Failure to understand the potential impact of strategic responses and business plans on existing risk types
• Failure to respond or the inappropriate strategic response to material changes in the external or internal operating environments
EXPOSURES
The Group faces significant risks due to the changing regulatory and competitive environments in the financial services sector, with an increased pace, scale and complexity of change. Customer, shareholder and employee expectations continue to evolve and current societal trends are being accelerated following the COVID-19 pandemic.
Strategic risks can manifest themselves in existing principal risks or as new exposures which could adversely impact the Group and its businesses.
In considering strategic risks, a key focus is the interconnectivity of individual risks and the cumulative effect of different risks on the Group’s overall risk profile.
The Group has invested in implementing a robust framework for the identification, assessment and quantification of strategic risks and their incorporation into business planning and strategic investment decisions. With Board support, the Group will continue to invest in evolving the strategic risk management framework and embedding it into the Group's day-to-day business operations.
MEASUREMENT
The Group assesses and monitors strategic risk implications as part of business planning and in its day-to-day activities, ensuring they respond appropriately to internal and external factors including changes to regulatory, macroeconomic and competitive environments. An assessment is made of the key strategic risks that are considered to impact the Group, leveraging internal and external information and the key mitigants or actions that could be taken in response.
2021 saw development of the Group’s quantitative risk assessment approach, assessing the:
• Connectivity of inherent risks, which can magnify their impact and severity
• Time horizons in respect of the crystallisation of impacts, should risks manifest
MITIGATION
The range of mitigating actions includes the following:
• Horizon scanning is conducted across the Group to identify potential threats, risks, emerging issues and opportunities and to explore future trends
• The Group’s business planning processes include formal assessment of the strategic risk implications of new business, product entries and other strategic initiatives
• The Group’s governance framework mandates individuals' and committees' responsibilities and decision-making rights, to ensure that strategic risks are appropriately reported and escalated
MONITORING
A review of the Group’s strategic risks is undertaken on an annual basis and the findings are reported to the Group and Board Risk Committees.
Risks, alongside their control effectiveness, are articulated and reported regularly to Group and Board Risk Committees.
Strategic risk is a significant source of risk for the Group, influencing the Group’s strategy, business model, performance and risk profile.
Significant work has been undertaken during 2021 to understand the risk implications of the Group’s strategy and the key drivers of strategic risk.
Key mitigating actions:
• Considering the strategic implications of emerging trends and addressing them through our strategy
• Integration of strategic risk into business planning process and embedding into day-to-day risk management
Strategic risk themes
Understanding the potential risk implications of our strategy is an important area of focus. Using both quantitative and qualitative analysis, key strategic risk themes have been identified and assessed (see below). These risks are aligned to the key areas of focus in the Group’s strategy and can result on impacts in the Group’s wider principal risks.
Organisational purpose: An organisational purpose with clear underlying principles and mission statements will enable us to build a more profitable and sustainable business for the Group’s stakeholders. Risks may arise from:
• Conflicting interpretation of the key principles and mission statement
• Inability to inspire the culture and galvanise the organisation to support a progressive strategy
• Stated purpose failing to resonate with our stakeholders due to conflicting objectives
Customer proposition: Risk of adverse impacts on reputation, customer attraction, customer retention and income generation, arising from:
• Inappropriate products and services
• Inability to respond to changing customer profiles and needs
• Failure to maintain trust and deepen relationships
Talent attraction and retention: Inability to meet the Group’s customer, colleague and transformation goals due to:
• Competition for specialist skills in a challenging labour market
• Failure to attract, develop and retain talent and capabilities for delivering the Group’s agenda
Climate change: Failure to:
• Adapt to shifting consumer and colleague expectations
• Achieve regulatory and external climate commitments
• Support the transition to a low carbon economy as both a lender and employer
Technology advances: Potential for greater operational costs, reduced resilience and uncompetitive or inappropriate customer offering, driven by:
• Failure to keep pace with advances in technology
• Inability to effectively leverage data, while ensuring strong data ethics
• Misalignment of technology versus customer appetite
Strategic Risk, important parts from the 2021 Annual Report, Citigroup Inc.
Strategic risk is the risk of a sustained impact (not episodic impact) to Citi’s core strategic objectives as measured by impacts on anticipated earnings, market capitalization, or capital, arising from the external factors affecting the Company’s operating environment; as well as the risks associated with defining the strategy and executing the strategy, which are identified, measured and managed as part of the Strategic Risk Framework at the Enterprise Level.
The Group Strategic Risk Committee (GSRC) provides governance oversight of Citi’s management actions to adequately identify, monitor, report, manage and escalate all material strategic risks facing Citi.
Risk Factors, Strategic Risk
Rapidly Evolving Challenges and Uncertainties Related to the COVID-19 Pandemic in the U.S. and Globally Will Likely Continue to Have Negative Impacts on Citi’s Businesses and Results of Operations and Financial Condition.
The COVID-19 pandemic has affected all of the countries and jurisdictions in which Citi operates, including severely impacting global health, financial markets, consumer and business spending and economic conditions.
The extent of the future pandemic impacts remain uncertain and will likely evolve by region, country or state, largely depending on the duration and severity of the public health consequences, including the duration and further spread of the coronavirus as well as any variants becoming more prevalent and impactful; further production, distribution, acceptance and effectiveness of vaccines; availability and efficiency of testing; the public response; and government actions.
The future impacts to global economic conditions may include, among others:
• further disruption of global supply chains;
• higher inflation;
• higher interest rates;
• significant disruption and volatility in financial markets;
• additional closures, reduced activity and failures of many businesses, leading to loss of revenues and net losses;
• further institution of social distancing and restrictions on businesses and the movement of the public in and among the U.S. and other countries; and
• reduced U.S. and global economic output.
The pandemic has had, and may continue to have, negative impacts on Citi’s businesses and overall results of operations and financial condition, which could be material.
The extent of the impact on Citi’s operations and financial performance, including its ability to execute its business strategies and initiatives, will continue to depend significantly on future developments in the U.S. and globally.
Such developments are uncertain and cannot be predicted, including the course of the coronavirus, as well as any weakness or slowing in the economic recovery or a further economic downturn, whether due to further supply chain disruptions, inflation trends, higher interest rates or otherwise.
The pandemic may not be sufficiently contained for an extended period of time. A prolonged health crisis could reduce economic activity in the U.S. and other countries, resulting in additional declines or weakness in employment trends and business and consumer confidence.
These factors could negatively impact global economic activity and markets; cause a continued decline in the demand for Citi’s products and services and in its revenues; further increase Citi’s credit and other costs; and may result in impairment of long-lived assets or goodwill.
These factors could also cause an increase in Citi’s balance sheet, risk-weighted assets and ACL, resulting in a decline in regulatory capital ratios or liquidity measures, as well as regulatory demands for higher capital levels and/or limitations or reductions in capital distributions (such as common share repurchases and dividends). Moreover, any disruption or failure of Citi’s performance of, or its ability to perform, key business functions, as a result of the continued spread of COVID-19 or otherwise, could adversely affect Citi’s operations.
The impact of the pandemic on Citi’s consumer and corporate borrowers will vary by sector or industry, with some borrowers experiencing greater stress levels, particularly as credit and customer assistance support further winds down, which could lead to increased pressure on their results of operations and financial condition, increased borrowings or credit ratings downgrades, thus likely leading to higher credit costs for Citi.
These borrowers include, among others, businesses that are more directly impacted by the institution of social distancing, the movement of the public and store closures. In addition, stress levels ultimately experienced by Citi’s borrowers may be different from and more intense than assumptions made in prior estimates or models used by Citi, resulting in an increase in Citi’s ACL or net credit losses, particularly as the benefits of fiscal stimulus and government support programs diminish.
Ongoing legislative and regulatory changes in the U.S. and globally to address the economic impact from the pandemic could further affect Citi’s businesses, operations and financial performance. Citi could also face challenges, including legal and reputational, and scrutiny in its efforts to provide relief measures.
Such efforts have resulted in, and may continue to result in, litigation, including class actions, and regulatory and government actions and proceedings. Such actions may result in judgments, settlements, penalties and fines adverse to Citi. In addition, the different types of government actions could vary in scale and duration across jurisdictions and regions with varying degrees of effectiveness.
Citi has taken measures to maintain the health and safety of its colleagues; however, these measures could result in additional expenses, and illness of employees could negatively affect staffing for a period of time. In addition, Citi’s ability to recruit, hire and onboard colleagues in key areas could be negatively impacted by pandemic restrictions as well as Citi’s COVID-19 vaccination requirement (see the qualified colleagues risk factor below).
Further, it is unclear how the macroeconomic or business environment or societal norms may be impacted after the pandemic. The post-pandemic environment may undergo unexpected developments or changes in financial markets, fiscal, monetary, tax and regulatory environments and consumer customer and corporate client behavior.
These developments and changes could have an adverse impact on Citi’s results of operations and financial condition. Ongoing business and regulatory uncertainties and changes may make Citi’s longer-term business, balance sheet and strategic and budget planning more difficult or costly. Citi and its management and businesses may also experience increased or different competitive and other challenges in this environment. To the extent that it is not able to adapt or compete effectively, Citi could experience loss of business and its results of operations and financial condition could suffer (see the competitive challenges risk factor below).
You may visit:
Artificial Superintelligence Risk
Membership and certification
In the Reading Room (RR) of the association you can find our newsletter. Our Reading Room
